To configure a policy for site B, perform the following steps:

Open the
WebUI. For more information on accessing the WebUI, go to
Accessing Your NetScreen, SSG, or ISG Firewall Using the WebUI

From the Juniper firewall menu, click
Policies.


From the
Policies page, in the
From drop-down menu, click to select
Trust, and in the
To drop-down menu, click to select
Untrust.


Click
New.

From
Source Address, in the
New Address text box, enter site B's trust IP address/netmask.

In this example, we entered
172.16.10.0 / 255.255.255.0.


From
Destination Address, in the
New Address text box, enter site A's trust IP address/netmask.

In this example, we entered
10.1.1.0 / 255.255.255.0.

From the
Action drop-down menu, click to select
Tunnel.


From the
Tunnel drop-down menu, click to select the VPN tunnel.

For this example, we selected
Site A VPN.

Click to select
Modify matching bidirectional VPN policy.


Click to select
Position at Top.

Click
OK.
